Vulnerability Intelligence Report
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
CVE-2026-59688
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
Injection
No Active Exploit Signals
CVSS Base Score
8.4
HIGH
Exploitability:1.7
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Progress Software | LoadMaster | 7.2.40.0 < 7.2.63.3 (affected), 7.2.40.0 < 7.2.54.19 (affected) |
| Progress Software | ECS Connection Manager | 7.2.60.0 < 7.2.63.3 (affected) |
| Progress Software | Object Scale Connection Manager | 7.2.60.0 < 7.2.63.3 (affected) |
| Progress Software | MOVEit WAF | 7.2.60.0 < 7.2.63.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Vulnerability Class
Injection
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Progress Software Corporation · Vendor · USA |
| Reserved | 2026-07-06T13:14:43 |
| Published | 2026-07-27T12:24:23 |
| Last Updated | 2026-07-28T03:55:34 |
Community Chatter & Buzz